The provider who created your medical record owns the physical chart or electronic file, but you own the health information inside it. That split is the answer to the question of who owns the information in patient medical records: the doctor’s office or hospital is the legal custodian of the document, while federal law gives you enforceable rights over the facts documented within. The provider stores and protects the file. You decide who sees what it says, and you can demand copies, corrections, and an accounting of where the information has gone.
The File Belongs to the Provider, the Information Belongs to You
When a clinician writes a note, orders a lab, or scans an image, the resulting document is the property of the practice or facility that created it. That ownership comes with duties: keep the record secure, keep it usable, and preserve it for as long as applicable law requires. Most states follow this framework by statute or long practice.
Owning the chart does not mean owning the facts on it. The Health Insurance Portability and Accountability Act, known as HIPAA, treats the provider as a steward of your protected health information. They hold it. You direct it. A provider cannot refuse to release information simply because they typed it, and nearly every patient right under federal law flows from this distinction.
What Your Rights Over the Information Actually Cover
HIPAA gives you four practical powers over the health information a provider maintains about you: to see and copy it, to correct it, to find out where it has been shared, and to control (within limits) further disclosures.
Access and Copies
You have the right to see and obtain a copy of nearly everything a provider maintains about you, including clinical notes, lab results, medical images, billing records, and insurance information. Anything used to make decisions about your care is included.1HHS.gov. Individuals’ Right under HIPAA to Access their Health Information 45 CFR 164.524
The provider must give you access within 30 calendar days of your request. That is an outer limit. One 30-day extension is allowed, but only if the provider notifies you in writing during the first 30 days, explains the delay, and commits to a specific new date.1HHS.gov. Individuals’ Right under HIPAA to Access their Health Information 45 CFR 164.524 Some states require faster turnaround, and where a state rule is more protective than HIPAA it still applies. Less-protective state rules are preempted.
Fees are tightly limited. A provider can charge for the labor of copying, for supplies like paper or a USB drive, and for postage if you asked for mail delivery. They cannot bill you for searching or retrieving the file.2eCFR. 45 CFR 164.524 Access of Individuals to Protected Health Information For records already stored electronically, providers have an optional shortcut: a flat fee of no more than $6.50 per request instead of calculating actual costs. That $6.50 figure is a convenience option, not a cap on all fees.3HHS.gov. $6.50 Flat Rate Option is Not a Cap on Fees State per-page caps often apply to paper copies, so ask about the total before a large paper request is filled.
The 21st Century Cures Act reinforced electronic access by defining “information blocking” as a violation. Providers, health IT developers, and health information networks that interfere with electronic sharing of health information, outside recognized exceptions, face regulatory action.4ASTP. Information Blocking This is why most practices now push results and notes to patient portals shortly after they are generated. If a provider insists you must come in person or wait weeks for records that already exist electronically, they may be crossing that line.
Corrections
When you find an error, HIPAA lets you ask the provider to amend the record. Put the request in writing and identify what you believe is wrong or incomplete. The provider has 60 days to act.5eCFR. 45 CFR 164.526 Amendment of Protected Health Information
A denial is allowed in limited situations, such as when the provider determines the record is already accurate and complete, or when the information originated with a different provider still available to address it. If your amendment is denied, you can submit a written statement of disagreement, and the provider must attach it to the record so anyone reviewing the file later sees your objection alongside the original entry.5eCFR. 45 CFR 164.526 Amendment of Protected Health Information
An Accounting of Where the Information Has Gone
You can ask for a report of who your health information has been disclosed to over the previous six years. This accounting covers disclosures made for reasons other than routine treatment, payment, and healthcare operations.6eCFR. 45 CFR 164.528 Accounting of Disclosures of Protected Health Information
Each entry must show the date, the recipient’s name and address if known, a brief description of what was shared, and why. Your first accounting in any 12-month period is free. For additional requests within the same year, the provider may charge a reasonable fee, but must tell you the amount upfront and let you narrow or withdraw the request.6eCFR. 45 CFR 164.528 Accounting of Disclosures of Protected Health Information
Where Your Control Stops
Your rights over the information are broad, not unlimited. HIPAA lists specific situations in which access can be denied.
- Psychotherapy notes kept separate from the main medical record receive extra protection, and providers are not required to release them.7HHS.gov. HIPAA Privacy Rule and Sharing Information Related to Mental Health
- Information compiled in anticipation of a civil, criminal, or administrative proceeding can be withheld.
- If you consented to a temporary suspension of access as part of enrolling in a clinical trial, the provider can hold your records until the study ends.
- A correctional facility can deny an inmate a copy if release would threaten health, safety, or security, though the inmate may still inspect the records in person.
- A licensed professional may deny access if, in their professional judgment, release is reasonably likely to endanger someone’s life or physical safety. Concern about emotional distress is not enough.1HHS.gov. Individuals’ Right under HIPAA to Access their Health Information 45 CFR 164.524
Certain denials, including the safety-threat exception, are reviewable. You can require that a different licensed professional, not involved in the original decision, take a second look.
Who Can Exercise These Rights on Your Behalf
HIPAA recognizes “personal representatives” who step into your shoes for access and control purposes.
Minor Children
A parent or legal guardian is generally the personal representative for a minor and can access the child’s records.8HHS.gov. Personal Representatives and Minors Exceptions apply when the child lawfully consented to care on their own under state law (for treatments like substance abuse services or reproductive health care), when a court ordered the treatment, or when the parent agreed to a confidential relationship between the child and provider. A provider may also exclude a parent when it reasonably believes the child has been or may be subjected to abuse or neglect.9HHS.gov. The HIPAA Privacy Rule and Parental Access to Minor Children’s Medical Records
Incapacitated Adults and Deceased Patients
If you have signed a healthcare power of attorney, that agent becomes your personal representative and can access records as needed to make decisions for you. After death, the executor or administrator of the estate takes that role.10HHS.gov. Personal Representatives
HIPAA protection does not end at death. A deceased person’s health information remains protected for 50 years after the date of death, after which HIPAA no longer applies to it.11HHS.gov. Health Information of Deceased Individuals That protection rule does not require providers to actually keep the records for 50 years; they may destroy them whenever state or other applicable law permits.12HHS.gov. Am I Required to Keep the Decedent’s Information for 50 Years
When a Provider Won’t Cooperate
Rights matter only if you can enforce them. HHS made right-of-access enforcement a priority in 2019, and settlements have kept coming. In one recent case, a patient made six requests over more than a year before getting his records, and the provider paid $112,500 to resolve the resulting investigation.13HHS.gov. HHS’ Office for Civil Rights Settles HIPAA Right of Access
If a provider ignores or unreasonably delays your request, file a complaint with the HHS Office for Civil Rights. The complaint must be in writing, must name the provider, must describe what happened, and must be filed within 180 days of when you became aware of the violation. OCR can extend that window for good cause. You can file through the online OCR Complaint Portal, by email to OCRComplaint@hhs.gov, or by mailing a form to HHS in Washington, D.C.14HHS.gov. How to File a Health Information Privacy or Security Complaint
Providers found in violation face civil monetary penalties that scale with the severity of the conduct, from a minimum tier for violations the provider did not know about, up to a top tier that reaches $2,190,294 per violation for willful neglect left uncorrected for more than 30 days.15Federal Register. Annual Civil Monetary Penalties Inflation Adjustment Most cases settle well below the maximums, but the pattern is consistent: OCR investigates, and providers who stonewall pay. Put every request in writing, keep copies, and note the dates. If you have to escalate, that paper trail is what makes your rights over your information real.